Spear Phishing

Phishing is just spam being used to trick people into revealing some information to the phisher, and relies very heavily on social engineering to succeed. By blocking spam effectively, the bait never reaches its target, and the opportunity for deception is crushed.

Phishers are now sending more targeted emails to businesses and these e-mails are designed to appear as though they were sent by another member of staff at the same organization, typically from the IT or HR departments. It seems that people will share their passwords fairly willingly via e-mail if the trust the source. It doesn’t hurt that this new breed of phisher promises treats to those who cooperate or threatens the employment of those who don’t.

In a recent US example, a phisher bluffed his way into the network of a port authority by spoofing an internal email address. Once on the inside, with an apparently genuine email identity, he was able to fool employees into revealing passwords for applications.

This sort of attack has been termed ‘spear’ phishing, designed to bamboozle unsuspecting ‘colleagues’ into revealing information that will give the perpetrator access into secure areas of corporate networks.

By spear phishing one company at a time, a phisher need only send emails to a single domain, spoofing the sender address and requesting usernames and passwords to validate some information, or providing a link to a spoofed version of the company’s website or intranet - or perhaps that of a business partner or supplier.

Many people often use the same username and password for different applications or websites, and the phisher may try and use that to their advantage in their social engineering.

It is surprisingly easy to use existing spam-sending software to dynamically generate the target email addresses, for example by combining databases of first names and last names with letters and numbers. Furthermore, it would only take a few hundred such permutations to provide a valid email address in a large organization.

Additionally, a sustained attack of this nature can quickly become a huge drain on the company’s email server, sapping its resources as it attempts to handle several hundred or thousand connections for emails that can never be delivered to recipients that don’t exist.

Nevertheless, a successful spear phishing expedition can reduce the effort required to break into a company’s network without too much difficulty.

Not only are the individual’s details potentially compromised; it can also lead to theft of intellectual property and other sensitive corporate information. Spear phishing is growing fairly quickly as a threat to corporations.

More

The opinions and views expressed in comments, blogs, etc. are those of the authors alone and not necessarily those of TMC, TMCnet, or its editors. TMCnet reserves the right to edit, delete, or otherwise make changes to the content that appears on these pages at its own discretion and as it deems necessary.
| 2 Comments | 1 TrackBack

Listed below are links to sites that reference Spear Phishing:

Spear Phishing TrackBack URL : http://blog.tmcnet.com/mt/mt-tb.cgi/8882

I am at a good friend's house today and they have a problem with their laptop. My friend is a lawyer and while we debate the merits of the Cisco vs. Apple iPhone case I am also helping fix their... Read More

2 Comments

Now you can fight back against these Phishers. Just enter the Phishers URL in http://www.PhishFighting.com and watch as 100's or 1000's of fake entries are continuously sent to the Phishers website. They won't be able to distinguash between real entries and the fake ones. Join the fight against Phishers.

Interesting article. Three years later, I am starting to see these attacks. They will only continue to grow, as the Phishers find more creative ways to lure users in.

Here is a hypothetical example, about Trust and Social
Networks: The New Frontier of Phishing:
http://blog.maysoft.org/blog.nsf/d6plinks/FPAO-7MKJL2

Leave a comment

Recent Activity

Today

More...

Recent Comments

  • kral oyun: Hi. I agree in principal with your ideas at the read more
  • Backbooner: xG is dead, totally dead! No one has any commercial read more
  • uglyphilkarn: Probably because they haven´t lied at all and anyone who read more
  • Mhay M. Gonzales: its nice read more
  • Wiliam: I've been looking at this company now and then for read more
  • Blatant Lying: The scary thing is they are forever claiming to ACTUALLY read more
  • Backbooner: "uglyphilkarn | November 24, 2009 12:17 AM | Reply Bart, read more
  • uglyphilkarn: Bart, you are a babbling fucking idiot. read more
  • Bart: I knew the moment xG announced the showcase and invited read more
  • Rusty: I signed up for Lingo on October 12th, 2009. The read more

Subscribe to Blog

Blogroll

Recent Entry Images

  • sagem-interstar-xmediusfax-outbound.png
  • tmcnet-feature-plaer-jquery-javascript.jpg
  • monopoly.jpg
  • itexpo-east-2009-exhibit-hall-aisle.jpg

Archives

Around TMCnet Blogs

  • Communications and Technology Blog - Tehrani.com:
    Happy Thanksgiving 2009
  • On Rad's Radar?:
    Open Neutral Fair
  • VoIP & Gadgets Blog:
    Nokia N900 Maemo 5 Bakes in Skype
  • Communications and Technology Blog - Tehrani.com:
    Interop New York 2009 Videos
  • First Coffee:
    Helpstream and CRM, Scalable Video Coding, Gemalto, Samsung Mobile
  • On Rad's Radar?:
    Mainly Cellular News Tidbits
  • The Readerboard:
    Want To Make Money? Shape Up Your Voice Self-Service
  • VoIP & Gadgets Blog:
    iLive ISP209B Portable Speaker System Review - Alarm Clock
  • Latest Whitepapers

    TMCnet Videos